ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0657×

19 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareBLUELIGHT

BLUELIGHT can collect IP information from the victim’s machine.

T1027.013
Encrypted/Encoded File
MalwareBLUELIGHT

BLUELIGHT has a XOR-encoded payload.

T1033
System Owner/User Discovery
MalwareBLUELIGHT

BLUELIGHT can collect the username on a compromised host.

T1041
Exfiltration Over C2 Channel
MalwareBLUELIGHT

BLUELIGHT has exfiltrated data over its C2 channel.

T1057
Process Discovery
MalwareBLUELIGHT

BLUELIGHT can collect process filenames and SID authority level.

T1070.004
File Deletion
MalwareBLUELIGHT

BLUELIGHT can uninstall itself.

T1071.001
Web Protocols
MalwareBLUELIGHT

BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API.

T1082
System Information Discovery
MalwareBLUELIGHT

BLUELIGHT has collected the computer name and OS version from victim machines.

T1083
File and Directory Discovery
MalwareBLUELIGHT

BLUELIGHT can enumerate files and collect associated metadata.

T1102.002
Bidirectional Communication
MalwareBLUELIGHT

BLUELIGHT can use different cloud providers for its C2.

T1105
Ingress Tool Transfer
MalwareBLUELIGHT

BLUELIGHT can download additional files onto the host.

T1113
Screen Capture
MalwareBLUELIGHT

BLUELIGHT has captured a screenshot of the display every 30 seconds for the first 5 minutes after initiating a C2 loop, and then once every five minutes thereafter.

T1124
System Time Discovery
MalwareBLUELIGHT

BLUELIGHT can collect the local time on a compromised host.

T1497.001
System Checks
MalwareBLUELIGHT

BLUELIGHT can check to see if the infected machine has VM tools running.

T1518.001
Security Software Discovery
MalwareBLUELIGHT

BLUELIGHT can collect a list of anti-virus products installed on a machine.

T1539
Steal Web Session Cookie
MalwareBLUELIGHT

BLUELIGHT can harvest cookies from Internet Explorer, Edge, Chrome, and Naver Whale browsers.

T1555.003
Credentials from Web Browsers
MalwareBLUELIGHT

BLUELIGHT can collect passwords stored in web browers, including Internet Explorer, Edge, Chrome, and Naver Whale.

T1560
Archive Collected Data
MalwareBLUELIGHT

BLUELIGHT can zip files before exfiltration.

T1560.003
Archive via Custom Method
MalwareBLUELIGHT

BLUELIGHT has encoded data into a binary blob using XOR.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.